CVE-2024-55636

Drupal core - Less critical - Gadget chain - SA-CORE-2024-006

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so called gadget chain presents no direct threat, but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.


We have discovered 103,755 live websites that are affected by CVE-2024-55636.

Run a Free Instant Scan




Affected Software

Product  Drupal
Category Content Management System
Vulnerable Domains103,755 live websites (50% of Drupal install base)
Vulnerable Versions
  • from 8 through 10.2.11
  • from 10.3 through 10.3.9
  • from 11 through 11.0.8
Vulnerable Versions Count247 versions ( 73% of all versions)


Common Weakness Enumeration

CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes



Details

  • Published - Dec 9, 2024
  • Updated - Dec 16, 2024

Credits

  • Drew Webber (finder)
  • Drew Webber (remediation developer)
  • Lee Rowlands (remediation developer)
  • Juraj Nemec (coordinator)
  • Benji Fisher (coordinator)
  • xjm (coordinator)

Website Distribution by Country

Number of websites using CVE-2024-55636
United States36,673 websites



Germany9,934 websites
France7,976 websites
Belgium5,003 websites
GB3,973 websites
Netherlands3,576 websites
Russia3,279 websites
Canada2,840 websites
Italy2,579 websites
Spain2,363 websites

Website Distribution by TLD

Number of websites using CVE-2024-55636
.com27,352 websites
.org9,897 websites
.de6,443 websites
.edu6,410 websites
.be4,990 websites
.fr4,478 websites
.nl3,223 websites
.ru2,600 websites
.ca2,087 websites
.it2,010 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-55636

Top websites that are affected by CVE-2024-55636. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.**.uk GB***
*********.com United States***
***.gov United States***
*******.gov United States*,***
***.gov United States*,***
***.gov United States*,***
******.com United States*,***
*******.com United States*,***
***.org United States*,***
***.*******.edu United States*,***
See full domain list

FAQ

CVE-2024-55636 is Improperly Controlled Modification of Dynamically-Determined Object Attributes in Drupal
A total of 103,755 websites have been identified as vulnerable to CVE-2024-55636, based on global website indexing conducted by WebTechSurvey.
The Drupal is affected by the CVE-2024-55636 vulnerability.
Drupal versions up to 11.0.8 are vulnerable to CVE-2024-55636.
CVE-2024-55636 is resolved in version 11.0.8 of Drupal.